Community discussions

MikroTik App
 
KDmitrii
just joined
Topic Author
Posts: 16
Joined: Wed Dec 09, 2015 8:32 am
Location: Kyrgyzstan

Transparent firewall

Wed Mar 22, 2017 12:24 pm

Hello Gentlemens!
Tell me please, can RouteOS to work in transparent mode firewall? Such as Cisco ASA.

The scheme is as follows: ISP --> Mikrotik SW --> multiple servers.
Task is to defend against DDOS or other intrusion from the outside my servers
 
User avatar
okazdal
Trainer
Trainer
Posts: 25
Joined: Fri Aug 07, 2015 4:44 pm
Contact:

Re: Transparent firewall

Wed Mar 22, 2017 2:05 pm

Hello,
You can have MikroTik work as a layer 3 stateful firewall. And I must add it is a very good stateful firewall. I have many customers who replaced their Cisco ASA with a CCR MikroTik router.

DDOS and intrusion prevention depends on the kind of the attack. You have very good tools to fight against DDoS attacks. But when you think about it if DDoS attack arrived at your firewall, that means it was successful.

MikroTik does not work like an application layer firewall like Palo Alto.

Osman Kazdal
 
KDmitrii
just joined
Topic Author
Posts: 16
Joined: Wed Dec 09, 2015 8:32 am
Location: Kyrgyzstan

Re: Transparent firewall

Wed Mar 22, 2017 5:23 pm

Thank you very much Osman Kazdal!
Can you tell me more about the settings of your equipment. How did you solve the problem with DDOS. Can you show me the rule or instruction.
I heard about PaloAlto, but unfortunately not dealt with them.

Best Regards
Dmitrii
 
R1CH
Forum Guru
Forum Guru
Posts: 1108
Joined: Sun Oct 01, 2006 11:44 pm

Re: Transparent firewall

Wed Mar 22, 2017 6:34 pm

A typical DDoS involves bandwidth exhaustion, you cannot defend against it without upstream filtering. By the time your firewall is inspecting the packets, your uplink is already saturated and useless.
 
User avatar
soulflyhigh
Member Candidate
Member Candidate
Posts: 180
Joined: Wed Sep 08, 2010 11:20 am

Re: Transparent firewall

Wed Mar 22, 2017 8:06 pm

A typical DDoS involves bandwidth exhaustion, you cannot defend against it without upstream filtering. By the time your firewall is inspecting the packets, your uplink is already saturated and useless.
Yes, the attacker simply saturate your internet connection with gigabits/sec of "junk traffic" BEFORE your firewall can do anything really useful.
Ask your ISP if they can offer you some kind of DDoS protection as a paid service.

Regards,
M.
 
User avatar
okazdal
Trainer
Trainer
Posts: 25
Joined: Fri Aug 07, 2015 4:44 pm
Contact:

Re: Transparent firewall

Thu Mar 23, 2017 11:04 am

Hi again,
I would suggest you watch MUM presentations by Tom Smyth and Wardner Maia. Their presentations are a great start to give you pointers and ideas about what you should do against DDoS.
Below are the links to their presentations. I think you can also find videos.
https://mum.mikrotik.com//presentations/US12/tom.pdf
https://mum.mikrotik.com//presentations ... 752556.pdf

Osman Kazdal

Who is online

Users browsing this forum: soulflyhigh and 45 guests